@platformatic/control
Platformatic Control
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:silent-process-exec | AI (semgrep): Legitimate runtime process management — spawns user-configured runtime argv as detached child processes, not attacker-controlled. | ai | |
| semgrep | semgrep:silent-process-exec-var | AI (semgrep): Same spawn call as silent-process-exec; stable false positive for this package's runtime control plane. | ai | |
| phantom-deps | phantom-dep:pino | AI (phantom-deps): pino is a declared runtime dep used via config/indirect references; stable FP for this package. | ai | |
| phantom-deps | phantom-dep:table | AI (phantom-deps): table is a declared runtime dep; stable FP for this package. | ai | |
| phantom-deps | phantom-dep:help-me | AI (phantom-deps): help-me is a declared runtime dep; stable FP for this package. | ai | |
| phantom-deps | phantom-dep:pino-pretty | AI (phantom-deps): pino-pretty is a declared runtime dep; stable FP for this package. | ai |
Versions (showing 51 of 91)
| Version | Deps | Published |
|---|---|---|
| 3.63.0 | 8 / 9 | |
| 3.62.5 | 8 / 9 | |
| 3.62.4 | 8 / 9 | |
| 3.62.3 | 8 / 9 | |
| 3.62.2 | 8 / 9 | |
| 3.62.1 | 8 / 9 | |
| 3.62.0 | 8 / 9 | |
| 3.61.1 | 8 / 9 | |
| 3.61.0 | 8 / 9 | |
| 3.60.0 | 8 / 9 | |
| 3.59.0 | 8 / 9 | |
| 3.58.1 | 8 / 9 | |
| 3.58.0 | 8 / 9 | |
| 3.57.0 | 8 / 9 | |
| 3.56.0 | 8 / 9 | |
| 3.55.0 | 8 / 9 | |
| 3.54.0 | 8 / 9 | |
| 3.53.0 | 8 / 9 | |
| 3.52.4 | 8 / 9 | |
| 3.52.3 | 8 / 9 | |
| 3.52.2 | 8 / 9 | |
| 3.52.1 | 8 / 9 | |
| 3.52.0 | 8 / 9 | |
| 3.51.0 | 8 / 9 | |
| 3.50.0 | 8 / 9 | |
| 3.49.1 | 8 / 9 | |
| 3.49.0 | 8 / 9 | |
| 3.48.0 | 8 / 9 | |
| 3.47.0 | 8 / 9 | |
| 3.46.0 | 8 / 9 | |
| 3.45.0 | 8 / 9 | |
| 3.44.0 | 8 / 9 | |
| 3.43.0 | 8 / 9 | |
| 3.42.0 | 8 / 9 | |
| 3.41.0 | 8 / 9 | |
| 3.40.0 | 8 / 9 | |
| 3.39.0 | 8 / 9 | |
| 3.38.1 | 8 / 9 | |
| 3.38.0 | 8 / 9 | |
| 3.37.0 | 8 / 9 | |
| 3.36.0 | 8 / 9 | |
| 3.35.1 | 8 / 9 | |
| 3.35.0 | 8 / 9 | |
| 3.34.1 | 8 / 9 | |
| 3.33.0 | 8 / 9 | |
| 3.32.0 | 8 / 9 | |
| 3.31.0 | 8 / 9 | |
| 3.30.0 | 8 / 9 | |
| 3.29.1 | 8 / 9 | |
| 3.29.0 | 8 / 9 | |
| 3.28.2 | 8 / 9 |
v3.63.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.62.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.62.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.62.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.62.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.62.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.62.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.61.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.61.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.60.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.59.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.58.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.58.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.